# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=73

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 74

---

## [Filebeat blocked after bulk file insertion](https://discuss.elastic.co/t/filebeat-blocked-after-bulk-file-insertion/315747)

<div class="topic-metadata">

**Author:** [@Marco\_Lagalla](https://discuss.elastic.co/u/Marco_Lagalla)\
**Replies:** 3\
**Last updated:** [October 5, 2022, 10:52am UTC](https://discuss.elastic.co/t/filebeat-blocked-after-bulk-file-insertion/315747 "2022-10-05T10:52:52Z")

</div>

Hi all, I am running an ELK platform where Filebeat is installed as agent in a container, monitoring a file written by Nginx. This nginx gets close to 30mln of requests at day. The ingestion of access logs is performin…

---

## [Metricbeat not able to recognise AWS modules](https://discuss.elastic.co/t/metricbeat-not-able-to-recognise-aws-modules/315661)

<div class="topic-metadata">

**Author:** [@Hasnain\_Raza](https://discuss.elastic.co/u/Hasnain_Raza)\
**Replies:** 4\
**Last updated:** [October 5, 2022, 7:17am UTC](https://discuss.elastic.co/t/metricbeat-not-able-to-recognise-aws-modules/315661 "2022-10-05T07:17:46Z")

</div>

Problem statement: Need to fetch logs from AWS resources ELB, cloudwatch, ecs etc. Need help in understanding the configs and why this error is coming. Metricbeat returns error Elastic version: 7.6.2 Exiting: 1 error:…

---

## [How can I increase the size of bytes that a log can have?](https://discuss.elastic.co/t/how-can-i-increase-the-size-of-bytes-that-a-log-can-have/315702)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 9\
**Last updated:** [October 4, 2022, 6:16pm UTC](https://discuss.elastic.co/t/how-can-i-increase-the-size-of-bytes-that-a-log-can-have/315702 "2022-10-04T18:16:02Z")

</div>

I need help, I am receiving a log of 1300 lines, I am receiving a parse error, for this I did tests and these logs were significantly reduced and with that the error disappears since what I am removing does not affect th…

---

## [Metricbeat is getting failed when we enable aws metricbeat moulde](https://discuss.elastic.co/t/metricbeat-is-getting-failed-when-we-enable-aws-metricbeat-moulde/315434)

<div class="topic-metadata">

**Author:** [@samadhan](https://discuss.elastic.co/u/samadhan)\
**Replies:** 2\
**Last updated:** [October 4, 2022, 3:07pm UTC](https://discuss.elastic.co/t/metricbeat-is-getting-failed-when-we-enable-aws-metricbeat-moulde/315434 "2022-10-04T15:07:32Z")

</div>

Hi Team, We have installed ELK monitoring with following beats version metricbeat version 7.9.0 (amd64), libbeat 7.9.0 \[b2ee705fc4a59c023136c046803b56bc82a16c8d built 2020-08-11 19:30:31 +0000 UTC\] packetbeat version p…

---

## [Trouble with nginx logs - filebeat configured but seeing gork error](https://discuss.elastic.co/t/trouble-with-nginx-logs-filebeat-configured-but-seeing-gork-error/315381)

<div class="topic-metadata">

**Author:** [@sunil106](https://discuss.elastic.co/u/sunil106)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 7:03am UTC](https://discuss.elastic.co/t/trouble-with-nginx-logs-filebeat-configured-but-seeing-gork-error/315381 "2022-10-04T07:03:02Z")

</div>

having trouble with parsing nginx logs. I am using nginx and running filebeat to push nginx logs directly to elasticsearch This are nginx caching servers that has following log format nginx log format log\_format cach…

---

## [Beats on multiple Cloud environments](https://discuss.elastic.co/t/beats-on-multiple-cloud-environments/314887)

<div class="topic-metadata">

**Author:** [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Replies:** 2\
**Last updated:** [October 3, 2022, 4:53pm UTC](https://discuss.elastic.co/t/beats-on-multiple-cloud-environments/314887 "2022-10-03T16:53:29Z")

</div>

Hello there" Working on a task to setup Elastic Cloud on AWS and some of the beats (meticbeat, heartbeat, filebeat, and packetbeat) are on AWS some of the beats need to be on Azure and GCP. In this situation,should we p…

---

## [Struggling with sonicwall module](https://discuss.elastic.co/t/struggling-with-sonicwall-module/315595)

<div class="topic-metadata">

**Author:** [@Philip\_Thomson1](https://discuss.elastic.co/u/Philip_Thomson1)\
**Replies:** 3\
**Last updated:** [October 3, 2022, 11:32am UTC](https://discuss.elastic.co/t/struggling-with-sonicwall-module/315595 "2022-10-03T11:32:07Z")

</div>

I am sure this is something silly, but I have been banging my head on this, I am trying to use the sonicwall module on filebeat 8.4 This is the sonicwall.yml: # Module: sonicwall # Docs: https://www.elastic.co/guide/en…

---

## [Filebeat sends encrypted logs from snort to elastic](https://discuss.elastic.co/t/filebeat-sends-encrypted-logs-from-snort-to-elastic/315625)

<div class="topic-metadata">

**Author:** [@mahmoudmaani](https://discuss.elastic.co/u/mahmoudmaani)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 7:21am UTC](https://discuss.elastic.co/t/filebeat-sends-encrypted-logs-from-snort-to-elastic/315625 "2022-10-03T07:21:05Z")

</div>

Hello, Snort logs on Kibana are encrypted as you can see below. Even when I try to run cat /var/log/snort/snort.log.166425312 on snort itself I will get the same output. The only way to show the output is by running…

---

## [Filebeat cannot communicate with Kibana](https://discuss.elastic.co/t/filebeat-cannot-communicate-with-kibana/315508)

<div class="topic-metadata">

**Author:** [@mahmoudmaani](https://discuss.elastic.co/u/mahmoudmaani)\
**Replies:** 8\
**Last updated:** [October 1, 2022, 4:41pm UTC](https://discuss.elastic.co/t/filebeat-cannot-communicate-with-kibana/315508 "2022-10-01T16:41:25Z")

</div>

Hello everyone, Filebeat is not working with my setup when I try to run ./filebeat setup -e I get the below error message. I have Elastic and Kibana installed on a single host and they are working well also, I have…

---

## [Does a log have a message space limit when processed by logstash with the xml filter?](https://discuss.elastic.co/t/does-a-log-have-a-message-space-limit-when-processed-by-logstash-with-the-xml-filter/315608)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 10:13pm UTC](https://discuss.elastic.co/t/does-a-log-have-a-message-space-limit-when-processed-by-logstash-with-the-xml-filter/315608 "2022-09-30T22:13:35Z")

</div>

I am working with an xml that contains very large logs (more than 1500 lines) and others with only one line, the large logs are giving me an error "Error parsing xml with XmlSimple", I have other logs with the same struc…

---

## [Barracuda Integration](https://discuss.elastic.co/t/barracuda-integration/315554)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 12:32pm UTC](https://discuss.elastic.co/t/barracuda-integration/315554 "2022-09-30T12:32:10Z")

</div>

I have configured the Barracuda integration to listen on a port number over UDP on Server A. I have also configured the Barracuda WAF to export log files to Server A using UDP. So, it looks ok, but I can't see data bei…

---

## [Filebeat memory usage is keep increasing](https://discuss.elastic.co/t/filebeat-memory-usage-is-keep-increasing/313597)

<div class="topic-metadata">

**Author:** [@SeungHyun\_Roh](https://discuss.elastic.co/u/SeungHyun_Roh)\
**Replies:** 5\
**Last updated:** [September 30, 2022, 12:10pm UTC](https://discuss.elastic.co/t/filebeat-memory-usage-is-keep-increasing/313597 "2022-09-30T12:10:12Z")

</div>

Hello, community! My colleague's struggling with some issue with filebeat in his project for 5 months, so every engineer in my team decided to help him. He's using filebeat 7.14.2 to collect logs and send it to kafka. …

---

## [Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/315545)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 10:41am UTC](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/315545 "2022-09-30T10:41:53Z")

</div>

We are receiving this error for a filbeat pod in a node on our kuberntes cluster. This specific filebeat pod seems to always be using a high amount of cpu. We wonder if this error message and the high cpu usage is linke…

---

## [About FileBeat Dissect processor](https://discuss.elastic.co/t/about-filebeat-dissect-processor/315138)

<div class="topic-metadata">

**Author:** [@aluopy](https://discuss.elastic.co/u/aluopy)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 8:02am UTC](https://discuss.elastic.co/t/about-filebeat-dissect-processor/315138 "2022-09-30T08:02:40Z")

</div>

HI, I want to use FileBeat's Dissect processor to handle my log simply, but always report an error. The relevant information is as follows: Version Info: elasticsearch: 8.4.2 kibana: 8.4.2 filebeat: 8.4.2 filebeat.yml:…

---

## [Filebeat not ingesting json based log files to elastic search](https://discuss.elastic.co/t/filebeat-not-ingesting-json-based-log-files-to-elastic-search/315482)

<div class="topic-metadata">

**Author:** [@paarbour](https://discuss.elastic.co/u/paarbour)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 10:34pm UTC](https://discuss.elastic.co/t/filebeat-not-ingesting-json-based-log-files-to-elastic-search/315482 "2022-09-29T22:34:08Z")

</div>

I have Elasticsearch and Kibana working, that was the easy part. I can ingest files directly from Kibana, no problems they get parsed and handled without issue. I am now trying to configure filebeat to pull in files fr…

---

## [Save a variable for use in processors or how to drop later events in a series?](https://discuss.elastic.co/t/save-a-variable-for-use-in-processors-or-how-to-drop-later-events-in-a-series/315406)

<div class="topic-metadata">

**Author:** [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Replies:** 3\
**Last updated:** [September 29, 2022, 4:30pm UTC](https://discuss.elastic.co/t/save-a-variable-for-use-in-processors-or-how-to-drop-later-events-in-a-series/315406 "2022-09-29T16:30:17Z")

</div>

Is it possible to save state in a variable for use in a processor? I'd like to do something like: - save\_variable: name: id value: winlog.event\_data.ScriptBlockId when: regexp: winl…

---

## [Packetbeat interfere with defender for identity on Windows Server 2012-2022](https://discuss.elastic.co/t/packetbeat-interfere-with-defender-for-identity-on-windows-server-2012-2022/314509)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 3\
**Last updated:** [September 29, 2022, 10:51am UTC](https://discuss.elastic.co/t/packetbeat-interfere-with-defender-for-identity-on-windows-server-2012-2022/314509 "2022-09-29T10:51:58Z")

</div>

Hi, We are using Packetbeat for capturing DNS traffic from our Windows servers (10 servers) and are having an issue with packetbeat interfering with the defender sensor. We are getting the following error message from D…

---

## [Multiple indices from one log file](https://discuss.elastic.co/t/multiple-indices-from-one-log-file/315290)

<div class="topic-metadata">

**Author:** [@kkovacs](https://discuss.elastic.co/u/kkovacs)\
**Replies:** 3\
**Last updated:** [September 29, 2022, 6:38am UTC](https://discuss.elastic.co/t/multiple-indices-from-one-log-file/315290 "2022-09-29T06:38:25Z")

</div>

Dear Community! I have a question regarding filebeat configuration. Is there any method to make two separate index from the same log file? My purpose is to make two separate index for Kibana from the same log file - to…

---

## [Filebeat Index with Module in Name -\> Alias and ILM](https://discuss.elastic.co/t/filebeat-index-with-module-in-name-alias-and-ilm/315346)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 0\
**Last updated:** [September 28, 2022, 9:50am UTC](https://discuss.elastic.co/t/filebeat-index-with-module-in-name-alias-and-ilm/315346 "2022-09-28T09:50:56Z")

</div>

Hello there, i do have the following situation. I run Filebeat on an dedicated server for the panw-Module, with a dedicated Port. Our Paloalto Firewall is shipping the logs via syslog to the filebeat-server. If i run f…

---

## [Found encoding issue with Filebeat MS SQL module](https://discuss.elastic.co/t/found-encoding-issue-with-filebeat-ms-sql-module/315351)

<div class="topic-metadata">

**Author:** [@imad\_orange](https://discuss.elastic.co/u/imad_orange)\
**Replies:** 0\
**Last updated:** [September 28, 2022, 10:03am UTC](https://discuss.elastic.co/t/found-encoding-issue-with-filebeat-ms-sql-module/315351 "2022-09-28T10:03:54Z")

</div>

Hello, For people who find a probleme to read files Error of SQL server with the module mssql, you should add encoding: utf-16le-bom in module\\mssql\\log\\config\\config.yml file. Thanks to @varun1992 (Found encoding iss…

---

## [Cannot parse suricata.eve.http.content\_range](https://discuss.elastic.co/t/cannot-parse-suricata-eve-http-content-range/315295)

<div class="topic-metadata">

**Author:** [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Replies:** 8\
**Last updated:** [September 27, 2022, 11:13pm UTC](https://discuss.elastic.co/t/cannot-parse-suricata-eve-http-content-range/315295 "2022-09-27T23:13:41Z")

</div>

I'm using the suricata module from beats 7.17.3 to parse suricata 6.0.4 EVE json logs and I'm getting the following parse error: "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for \[suricata.eve.…

---

## [Fleet Custom Logs integration add\_fields processor](https://discuss.elastic.co/t/fleet-custom-logs-integration-add-fields-processor/315070)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 11\
**Last updated:** [September 27, 2022, 8:25pm UTC](https://discuss.elastic.co/t/fleet-custom-logs-integration-add-fields-processor/315070 "2022-09-27T20:25:42Z")

</div>

Hello Team, we are trying to add fields to a Custom Logs integration via "Advanced settings" tried many formats but none of them is working: - processors: add\_fields: target: fields: foo:ba…

---

## [Filebeat 8.4.2 modules Panw : Panw modules does not parse log correctly](https://discuss.elastic.co/t/filebeat-8-4-2-modules-panw-panw-modules-does-not-parse-log-correctly/315299)

<div class="topic-metadata">

**Author:** [@soufiane\_adn](https://discuss.elastic.co/u/soufiane_adn)\
**Replies:** 0\
**Last updated:** [September 27, 2022, 6:17pm UTC](https://discuss.elastic.co/t/filebeat-8-4-2-modules-panw-panw-modules-does-not-parse-log-correctly/315299 "2022-09-27T18:17:50Z")

</div>

hello team, i found a problem with filebeat v 8.4.1 on parsing palo alto logs using panw modules. below the error: field \[generated\_time\] not present as part of path \[temp.generated\_time\] any help? PS: i received th…

---

## [Winlogbeat Sending Bad Json Message](https://discuss.elastic.co/t/winlogbeat-sending-bad-json-message/315271)

<div class="topic-metadata">

**Author:** [@Rohit\_Kumbhar](https://discuss.elastic.co/u/Rohit_Kumbhar)\
**Replies:** 0\
**Last updated:** [September 27, 2022, 2:16pm UTC](https://discuss.elastic.co/t/winlogbeat-sending-bad-json-message/315271 "2022-09-27T14:16:02Z")

</div>

Hi @elastic Team, All versions are 7.16.2 My Setup is Winlogbeat(logstash output)=\>(beats input)collector(logstash TCP output)=\> (tcp input)loadbalancer(elastic output) I am able to receive most of the data from serve…

---

## [Cisco Filebeat module (umbrella) - Improve ECS utilization](https://discuss.elastic.co/t/cisco-filebeat-module-umbrella-improve-ecs-utilization/315127)

<div class="topic-metadata">

**Author:** [@aforfot](https://discuss.elastic.co/u/aforfot)\
**Replies:** 2\
**Last updated:** [September 27, 2022, 7:15am UTC](https://discuss.elastic.co/t/cisco-filebeat-module-umbrella-improve-ecs-utilization/315127 "2022-09-27T07:15:28Z")

</div>

We are ingesting Cisco Umbrella data into our Elasticsearch for search, detection in Elastic Security and visualization through Kibana. However, we have noticed a few specific fields where the Cisco module does not optim…

---

## [Office 365 Filebeat Module - Improve ECS utilization](https://discuss.elastic.co/t/office-365-filebeat-module-improve-ecs-utilization/315126)

<div class="topic-metadata">

**Author:** [@aforfot](https://discuss.elastic.co/u/aforfot)\
**Replies:** 2\
**Last updated:** [September 27, 2022, 7:14am UTC](https://discuss.elastic.co/t/office-365-filebeat-module-improve-ecs-utilization/315126 "2022-09-27T07:14:29Z")

</div>

We are ingesting O365 data into our Elasticsearch for search, detection in Elastic Security and visualiation through Kibana. However, we have noticed a few areas for improvement within the module. What is most interestin…

---

## [Microsoft Filebeat Module - Lack of ECS utilization](https://discuss.elastic.co/t/microsoft-filebeat-module-lack-of-ecs-utilization/315125)

<div class="topic-metadata">

**Author:** [@aforfot](https://discuss.elastic.co/u/aforfot)\
**Replies:** 6\
**Last updated:** [September 27, 2022, 7:12am UTC](https://discuss.elastic.co/t/microsoft-filebeat-module-lack-of-ecs-utilization/315125 "2022-09-27T07:12:21Z")

</div>

We are ingesting Microsoft ATP and M365 Defender data into our Elasticsearch for search, detection in Elastic Security, and visualization through Kibana. However, we have noticed a few specific fields where the Microsoft…

---

## [Regarding duplicacy of logs through filebeat at kibana](https://discuss.elastic.co/t/regarding-duplicacy-of-logs-through-filebeat-at-kibana/314365)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 8\
**Last updated:** [September 27, 2022, 4:23am UTC](https://discuss.elastic.co/t/regarding-duplicacy-of-logs-through-filebeat-at-kibana/314365 "2022-09-27T04:23:34Z")

</div>

Hi, As attached screenshot of kibana, logs are repeated with same message in two format, only difference of it log.file.path as I seen here. These dhcp logs are coming through filebeat to kafka. Logs flow is: filebea…

---

## [Using leader election condition in fleet managed Custom Logs integration doesn't work](https://discuss.elastic.co/t/using-leader-election-condition-in-fleet-managed-custom-logs-integration-doesnt-work/314591)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 5:07pm UTC](https://discuss.elastic.co/t/using-leader-election-condition-in-fleet-managed-custom-logs-integration-doesnt-work/314591 "2022-09-26T17:07:01Z")

</div>

I have a fleet managed Daemonset of agents which are assigned a policy including the Custom Logs integration. I want to collect logs which are duplicated across all nodes, so I'm only interested in one of the agents ship…

---

## [Auditbeat monitor pod audit events](https://discuss.elastic.co/t/auditbeat-monitor-pod-audit-events/315147)

<div class="topic-metadata">

**Author:** [@masonlu2014](https://discuss.elastic.co/u/masonlu2014)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 8:58am UTC](https://discuss.elastic.co/t/auditbeat-monitor-pod-audit-events/315147 "2022-09-26T08:58:50Z")

</div>

hell team, we are using auditbeat run as pod on our k8s work node to monitor the releated audit events happen in node level which is running good, however, is that any possible to monitor audit events which happen in…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=72)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=74)
